Stancja Privacy Policy
30 September 2026
This Privacy Policy describes how personal data are processed in connection with the use of the Stancja mobile application and related websites and services (hereinafter: the Application or the Service). This document has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: the GDPR).
Who is responsible for your data (controller and processor)
Stancja involves two distinct roles with respect to personal data. The distinction matters because it determines to whom you should direct your requests.
1.1. Data controller - service provider. The controller of data related to the account, operation of the platform, and technical data of all users is:
- MICHAŁ KUKIEŁKA MIDDLY
- NIP: 5833449726, REGON: 521901211
- Address: ul. prof. Romualda Cebertowicza 8D/38, 80-809 Gdańsk, Poland
- Contact e-mail for data matters: hello@stancja.app
(hereinafter: the Service Provider or we).
As controller, we are responsible, among other things, for: the Landlord's account data, technical and diagnostic data of all users (including the Tenant), handling of e-mail messages (e.g. signature invitations), and the security and operation of the platform.
1.2. Processor - with respect to protocol content. With respect to the content of the handover protocol (photos, descriptions, condition ratings, personal data of the parties entered into the protocol), the data controller is the Landlord, i.e. the user who creates an account and creates the protocol. The Service Provider then acts as a processor, performing operations on behalf of the Landlord on the basis of a data processing agreement set out in the Terms of Service (§15).
After the end of the provision of services to the Landlord (e.g. after account deletion), with respect to retained signed protocols (§4.3), the Service Provider processes the data contained therein as a separate controller - solely for the purpose specified in §4.3 (the role change is described in §15(10) of the Terms of Service).
1.3. What this means in practice.
- If you are a Tenant and wish to exercise rights relating to the content of a specific protocol (e.g. access, rectification), direct your request to the Landlord, who is its controller. The Service Provider will provide the Landlord with the necessary technical assistance.
- For matters relating to technical data, the account, or the operation of the Application, the Service Provider is the controller and you should direct your request to it.
1.4. Data Protection Officer. The Service Provider is not required to appoint a Data Protection Officer and has not appointed one. For all data-related matters, you may contact the address indicated in §1.1.
What data we process, for what purpose, and on what legal basis
2.1. Landlord data (account holder)
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| E-mail address | Account creation and management, login, transactional messages | Art. 6(1)(b) GDPR (performance of a contract) | Until account deletion - see §4 |
| Password (in hashed form) (when registering by e-mail) | Authentication | Art. 6(1)(b) GDPR | Until account deletion |
| Profile data (first name or display name) | Account management | Art. 6(1)(b) GDPR | Until account deletion |
| Account identifier at the login provider (Google / Apple) and - if you share it - your name | Authentication and account creation via external login | Art. 6(1)(b) GDPR | Until account deletion |
External login (Sign in with Google / Sign in with Apple). You can create and access your Account using an e-mail address and password, or via the Google or Apple login service. With external login we receive from the provider only the data necessary to authenticate and create the Account: your e-mail address, a unique user identifier at the provider, and - if you share it - your name. With Apple you may use the "Hide My Email" option - instead of your real address we then receive a private relay address, which serves as your contact address and Account address. The legal basis is Art. 6(1)(b) GDPR (performance of the contract for the Account).
2.2. Data entered into the protocol (concerning both parties - Landlord and Tenant)
In this respect, the Landlord is the controller (§1.2); the description below is provided for clarity.
| Data | Purpose | Legal basis |
|---|---|---|
| Full names of the parties | Identification of the parties to the protocol | Art. 6(1)(b) and (f) GDPR |
| Party identifier (PESEL or identity document number) | Unambiguous identification of the parties for documentation and potential claims | Art. 6(1)(f) GDPR |
| Tenant's e-mail address | Sending a signature invitation and identity verification (mailbox access control) | Art. 6(1)(b) and (f) GDPR |
| Phone numbers of the parties | Contact between the parties regarding the protocol, identification | Art. 6(1)(b) and (f) GDPR |
| Address of the premises and addresses of the parties | Designation of the premises covered by the protocol and identification of the parties | Art. 6(1)(b) and (f) GDPR |
| Electronic signatures of the parties | Confirmation of statements contained in the protocol | Art. 6(1)(b) and (f) GDPR |
| Room descriptions, condition of items, ratings, remarks | Documentation of the condition of the premises | Art. 6(1)(b) and (f) GDPR |
| Photos | Documentation of the condition of the premises (evidentiary material for the parties) | Art. 6(1)(b) and (f) GDPR |
| Photo geolocation (GPS coordinates from EXIF metadata), where the photo contains them | Confirming where a photo was taken, as part of the evidentiary material | Art. 6(1)(f) GDPR |
| Integrity metadata (SHA-256 hashes, timestamps) | Detection of changes in documentation, confirmation of consistency | Art. 6(1)(f) GDPR |
Note regarding photos and third-party data. Photos and content are entered by the user. The user is responsible for ensuring that they do not contain personal data of third parties processed unlawfully and that there is a legal basis for their entry.
Note regarding photo geolocation. The App never requests access to your device location and does not determine your position. However, if a photo you add carries GPS coordinates previously written into its EXIF metadata by the camera, we read them and store them together with the photo. A photo without that metadata works exactly the same - providing this data is not required in order to use the App. You can prevent it by turning off location recording in your camera settings.
2.3. Technical and diagnostic data (concerning all users)
| Data | Purpose | Legal basis | Period |
|---|---|---|---|
| IP address | Security, abuse prevention, server logs | Art. 6(1)(f) GDPR | up to 12 months |
| Device data and Application version (device model, operating system version, Application version) | Diagnostics, ensuring operation | Art. 6(1)(f) GDPR | 90 days |
| Error logs / crash data (crash reports) | Detection and removal of errors, stability | Art. 6(1)(f) GDPR | 90 days |
Data recipients and processors (sub-processors)
We use trusted providers who process data on our behalf on the basis of data processing agreements (DPAs). Currently, these are:
- Cloudflare, Inc. - storage of photos and files (Cloudflare R2).
- Resend (resend.com) - sending of e-mail messages (invitations, transactional notifications).
- Railway Corp. - hosting of the server application and database.
- Vercel Inc. - hosting of the website and cookieless visit statistics (Vercel Web Analytics, see §9).
- Functional Software, Inc. (Sentry) - error and crash monitoring.
External login providers. If you use Google or Apple login, these providers - Google Ireland Limited (and Google LLC) and Apple Inc. (and Apple Distribution International Ltd.) - act as independent controllers for the authentication process on their side; we receive from them only the data described in §2.1. Data processing on the providers' side is governed by their own privacy policies.
Planned AI features (not yet active). In the future, we intend to offer features based on artificial intelligence (e.g. meter reading, recognition of room elements) using Amazon Web Services (AWS Bedrock) in the EU region. Until such features are launched, data are not transferred to this provider. This Policy will be updated before the launch of such features.
Data may also be disclosed to authorised authorities where required by law.
3.1. Transfers outside the European Economic Area (EEA)
Some providers may process data outside the EEA (including in the USA). In such cases, the transfer takes place on the basis of mechanisms provided for in the GDPR - in particular adequacy decisions (e.g. the EU-U.S. Data Privacy Framework, if the provider is certified) or standard contractual clauses (SCCs), in accordance with the data processing agreement of the relevant provider.
How long we retain data (retention) and what happens after account deletion
Retention rules reflect the nature of the Service: a protocol signed by both parties may constitute material relevant to the establishment, exercise, or defence of claims by either party to the lease.
4.1. Account and Service data - for as long as the account is held.
4.2. Draft versions and protocols that are unsigned or signed by only one party - deleted upon account deletion (permanent deletion). You may also delete them yourself at any time.
4.3. Protocols signed by both parties - after account deletion, retained as an immutable PDF file for a period of 6 years from the date of signing, after which they are permanently deleted. Database records during this period are limited to the necessary minimum (a technical "trace" of the account remains). The legal basis for further retention is Art. 17(3)(e) GDPR (data necessary for the establishment, exercise, or defence of legal claims) in conjunction with Art. 6(1)(f) GDPR.
The retained document may be made available to a party to the Protocol upon request submitted by e-mail to the address in §1.1. Verification of the requester consists in confirming access to the e-mail address assigned to the given party in the Protocol - a one-time link or confirmation code is sent to that address, and the document is made available only after confirmation.
4.4. Diagnostic data (error/crash reports) - 90 days.
4.5. Limitation with respect to signed protocols. For technical and evidentiary reasons, we do not modify or delete individual personal data from the content of an already signed protocol - the signatories' data are permanently embedded in the document covered by a cryptographic hash, and their alteration would compromise the integrity (and evidentiary value) of the document. This applies symmetrically to both parties.
Your rights
You have the rights arising from the GDPR. Direct them to the appropriate controller (see §1.3):
- right of access to data (Art. 15),
- right to rectification (Art. 16),
- right to erasure - the "right to be forgotten" (Art. 17), subject to exceptions, including §4.3 and §4.5,
- right to restriction of processing (Art. 18),
- right to data portability (Art. 20),
- right to object to processing based on Art. 6(1)(f) (Art. 21).
Complaint to a supervisory authority. You have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
Account and data deletion
You may delete your account and related data yourself:
- in the Application: Settings → Delete account,
- via the website: stancja.app/usun-konto,
- or by e-mail to the address in §1.1.
If you used Apple login, upon Account deletion we request revocation of the associated Apple token from Apple.
The effects of deletion are described in §4 (including permanent deletion of draft versions and retention of signed protocols for a period of 6 years).
Data security
We apply technical and organisational measures appropriate to the risk, including: transmission encryption, storage of passwords solely in hashed form, access control, and documentation integrity mechanisms (SHA-256 hashes). However, no system guarantees complete security - we recommend caution when sharing access credentials.
Data stored locally on the device
The Application stores some data locally on the device (including session data and temporary technical data, e.g. in the device's local storage) for proper operation. Uninstalling the Application removes this data from the device.
Cookies (website)
The website stores in your browser only the settings you choose yourself. We do not use analytics, marketing, or tracking cookies, and therefore do not display a cookie consent banner.
| Name | Type | Purpose | Retention |
|---|---|---|---|
| fs_web_theme | Cookie and browser local storage (localStorage) | Remembering the selected theme (light / dark) | 12 months |
| NEXT_LOCALE | Cookie | Remembering the selected language version of the website | 12 months |
Visit statistics. We use Vercel Web Analytics to learn which pages are visited and whether the website serves its purpose. The service does not store any cookies or other data on your device. It records the page visited, the referring page, country, device type, operating system and browser, as well as selected interactions: a click on an app store button, expanding a FAQ question, the mere fact of searching the FAQ (without the search query) and the mere fact of submitting the account or data deletion form (without the form contents). Visits within a single day are linked by a hash computed from request data, which is discarded after 24 hours - it does not allow us to recognise you on later visits or on other websites. We only have access to the data as aggregate statistics. The legal basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR) in measuring traffic and improving the website.
Children
The Service is intended for adults (18+), with full legal capacity. We do not direct the Service to children and do not knowingly collect their data.
Changes to the Policy
We may update this Policy. We will inform you of material changes in the Application or by e-mail. The current version is always available at the permanent address where this document is published.
Contact
For all matters relating to personal data: hello@stancja.app or by post to the address in §1.1.